Wireless Access

last person joined: 20 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

problems terminating Instant IPSEC tunnels on a 7210 controller

This thread has been viewed 0 times
  • 1.  problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:04 AM

    Hello Airheads,

    anyone have problems with Instant IPSEC tunnels terminating on 7210 controllers?

     

     


    #7210


  • 2.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:48 AM

    Hi friend,

     

    What is the issue ? I can help you on fixing the issue.

     

    Please feel free to share the issue.


    #7210


  • 3.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:51 AM

    hello Venu,

     

    we have Aruba Instant clusters in the field terminating VPN tunnels onto a 7210 controller

    we have set everything up e.g. VPN pool on the controller and peer gateway but we are getting this message in the logs when the tunnel doesn't form

     

    Jan 22 08:59:32 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 08:59:32 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 09:00:15 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 09:00:15 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:24:23 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:24:23 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:24:23 isakmpd[3352]: <103063> <DBUG> |ike|   *** ipc_auth_recv_packet user=24:de:c6:c6:51:0a, pass=******, result=0   ctx:7a7ca4, ctx-innerip:0.0.0.0 l2tp_pool:VPN-pool

    Jan 22 10:24:23 isakmpd[3352]: <103063> <DBUG> |ike|   get_ikev2_internal_ip pool VPN-pool

    Jan 22 10:24:44 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:24:44 isakmpd[3352]: <103063> <DBUG> |ike|   *** ipc_auth_recv_packet user=24:de:c6:c6:51:0a, pass=******, result=0   ctx:7a5d6c, ctx-innerip:0.0.0.0 l2tp_pool:VPN-pool

    Jan 22 10:24:44 isakmpd[3352]: <103063> <DBUG> |ike|   get_ikev2_internal_ip pool VPN-pool

    Jan 22 10:25:05 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:25:05 isakmpd[3352]: <103061> <ERRS> |ike|   Unable to get get IP Address from pool

    Jan 22 10:25:05 isakmpd[3352]: <103063> <DBUG> |ike|   *** ipc_auth_recv_packet user=24:de:c6:c6:51:0a, pass=******, result=0   ctx:7a53bc, ctx-innerip:0.0.0.0 l2tp_pool:VPN-pool

    Jan 22 10:25:05 isakmpd[3352]: <103063> <DBUG> |ike|   get_ikev2_internal_ip pool VPN-pool

     

    ani ideas?


    #7210


  • 4.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    EMPLOYEE
    Posted Jan 22, 2015 06:53 AM
    Do you have a vpn pool defined on the controller? 


    Thanks, 
    Tim
    #7210


  • 5.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:54 AM

     

    yes Tim we do

     


    #7210


  • 6.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:57 AM

    Hi

     

    Check whether the pool is exhausted ?


    #7210


  • 7.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 06:58 AM

     

    the pool has plenty of addresses spare

    Pete

     


    #7210


  • 8.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 07:12 AM

    Hi,

     

    The output is clearly saying it is issue with VPN pool. you have to work around the pool.

     

    If no other IPSec is terminated on the same controller, reset the Pool.

     

    Please feel free for any further query on this.


    #7210


  • 9.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 22, 2015 08:06 AM

    Please check the L2TP pool by running:

     

    show vpdn l2tp local pool


    #7210


  • 10.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller
    Best Answer

    Posted Jan 22, 2015 08:24 AM

    Make sure your pool on that controller is named VPN-pool (case sensitive); as that is what the IAP seems to be looking for in your setup.    Did you specify the pool that is used for the default-vpn-role by chance?


    #7210


  • 11.  RE: problems terminating Instant IPSEC tunnels on a 7210 controller

    Posted Jan 23, 2015 02:02 AM

    thank you for the reply my friend you were absolutely right it was a naming issue on the vpn pool.

    All working now

    Pete

     

    p.s. all the feedback was very good and all appreciated thank you

     


    #7210